Welcome to today’s NH-ISAC & MDISS Webinar
Medical Device Vulnerability Intelligence Program for Evaluation and Response (MD-VIPER)
1
Welcome to todays NH-ISAC & MDISS Webinar Medical Device - - PowerPoint PPT Presentation
Welcome to todays NH-ISAC & MDISS Webinar Medical Device Vulnerability Intelligence Program for Evaluation and Response (MD-VIPER) 1 Agenda SpeakerName SpeakerInstitution Topic Speaker check- in Everyone Soundcheck
1
2
SpeakerName SpeakerInstitution Topic Everyone Speaker check- in Soundcheck Recording on Denise Anderson NH-ISAC NH-ISAC and ISAO Standardized (ISAO) procedures
MOU overview Participation Jon Crosson NH-ISAC Using the site Finding help Reporting process Event tracking DaleNordenberg MDISS MD-VIPER Description Attributes Outcomes MichelleJump Stryker Decision to report flow diagram SteveAbrahamson GE Health Report process flow diagram MichaelMcNeil Philips Health Coordinateddisclosure All speakers Ken Hoyme RobertaHansen SteveGrimes QA
PDD-68 ISACs Established 1998 SafetyAct ISAOs Established NH-ISAC Established EO NIPP 2013 Partnership Post-Market Guidance MD-VIPER 2002 2010 2013 2016
almost 20 years old
sector formed and led
3
4
critical infrastructure owners and operators to gather, analyze, appropriately sanitize, and disseminate intelligence and information related to critical
capabilities and have the ability to reach and share information within their sectors, between sectors, and among government and private sector stakeholders. (Source: Presidential Decision Directive 63, 1998)
entity or collaboration created or employed by public or private sector
5
Information Sharing and Analysis Organizations Several private sector information sharing and analysis organizations have been established in the last decade. ISACs are examples of successful information-sharing
ISACs – ISACs serve as operational and dissemination arms for many sectors and subsectors, and facilitate sharing of information between government and the private sector. ISACs work closely with SCCs in the sectors where they are recognized. They are designed to provide in-depth sector analysis and help coordinate sector response during incidents, including information sharing within sectors, between sectors, and among public and private sector critical infrastructure stakeholders. Government agencies also may rely on ISACs for situational awareness and to enhance their ability to provide timely, actionable data to targeted entities.
Call to Action
6
Sharing Community Intelligence and Alerts Newsletter Exercises Webinars/Threat Calls Conferences & Workshops White Papers Working Groups/Committees Tools – Symphony, Soltra, Brightpoint Playbook & Threat Level CyberFit Special Interest Groups
7
8
*Need to register and sign NDA
9
MDSISC MD-VIPER Post- Market Guidance NH-ISAC MEMBERSHIP MD STAKEHOLDER PARTICIPATION
based and open to
membership criteria.
under the NH-ISAC co-led by
MDISS members..
/MDISS initiative open to medical device security stakeholders.
10
11
mitigation strategies
12
13
14
advises in writing to share the data
in writing, to share the data
process
manufacturer
15
EVENT# DATE COMPANY POCNAME PHONE NUMBER EMAIL PURPOSE OF EVENT FOLLOW UP ACTION
16
Vulnerability Information Sharing* in Support of FDAGuidance System Description
unloadable PDF file
MDVIS after it has evaluated the vulnerability
needed, to help ensure vulnerabilities are evaluated appropriately before sharing.
embargoed until coordinated disclosure is executed by manufacturer, ICS-CERT and FDA
17
*This work is executed under Memorandum of Understanding (MOU) 225-16-024 between FDA, NHISAC and MDISS; Published October 06,2016
Vulnerability Information Sharing* in Support of FDAGuidance Key Attributes
18
*This work is executed under Memorandum of Understanding (MOU) 225-16-024 between FDA, NHISAC and MDISS; Published October 06,2016
Vulnerability Information Sharing* in Support of FDAGuidance
20
*This work is executed under Memorandum of Understanding (MOU) 225-16-024 between FDA, NHISAC and MDISS; Published October 06,2016
Key Outcomes
and privacy profiles for devices and associated networks